fg742p.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from us.dongtaiwang.com.
MD5:
5857c47f9720e1c6289f697e644a75b8

SHA-1:
949f129b0b71adf491e617b71abe38a21143d714

SHA-256:
e2063fc89495be7ef604e3d3288a692ae07f68801c315df6432ab330b4b50032

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
2/25/2025 11:41:49 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Freegate.A potentially unsafe application
8.0.319.0

File size:
1.1 MB (1,175,062 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fg742p.exe

File PE Metadata
Compilation timestamp:
11/8/2013 10:32:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:TuRZ8HGtS6fhYVD3M01kP4+lU5zaLYwKp9gMBrEuh1ajr5NNbL:qRGHGtXhYVTM6kRWUs9gMBr/85NdL

Entry address:
0xA9FD3

Entry point:
52, BA, 64, 00, 00, 00, 85, D2, 74, 1D, B9, 00, 10, 00, 00, 85, C9, 74, 07, 01, C8, 01, D8, 49, EB, F5, 52, 54, 54, FF, 15, 33, 40, 5D, 00, 5A, 4A, EB, DF, 5A, E9, 00, B0, 48, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 06, 00, C8, 11, 00, 80, 48, 00, 00, 80, 03, 00, 00, 00, 78, 00, 00, 80, 04, 00, 00, 00, D8, 00, 00, 80, 05, 00, 00, 00, F0, 00, 00, 80, 06, 00, 00, 00, C0, 01, 00, 80, 0E, 00, 00, 00, 90, 02, 00, 80, 10, 00, 00, 00, B8, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9678  (probably packed)

Code size:
1.1 MB (1,183,744 bytes)

The file fg742p.exe has been seen being distributed by the following URL.

Scan fg742p.exe - Powered by Reason Core Security